FORTIBLEED CAMPAIGN STILL HITTING FORTINET FIREWALLS AND VPNS A joint FBI ...
Dark Web Intelligence on X: "🇺🇸 🚨 FBI AND SECRET SERVICE: FORTIBLEED CAMPAIGN STILL HITTING FORTINET FIREWALLS AND VPNS
A joint FBI and U.S. Secret Service cybersecurity advisory published Oct 6 says FortiBleed, a global credential-compromise campaign against internet-facing Fortinet FortiGate firewalls and SSL VPN gateways, is still active.
• Attackers keep scanning exposed FortiGate devices with previously stolen credentials, using credential stuffing, password spraying and GPU cracking of dumped password hashes
• The campaign exploits reused or leaked credentials and legacy SHA-256 password storage
• Once in, they create new admin accounts for persistence; some victims are locked out when original accounts are deleted or their passwords changed
• Reporting cited by the agencies indicates initial access brokers using the attack chain have passed access to INC/Lynx and Payload ransomware affiliates
• Restrict external management (trusted hosts, then local-in policy) or remove internet admin altogether
• Terminate all admin and VPN sessions; reset all Fortinet VPN and admin passwords
• Enforce phishing-resistant MFA on all remote access and admin accounts
• Review firewall/VPN users and config for unauthorized changes and unrecognized accounts
• Review firewall, VPN, authentication and domain controller logs for lateral movement
• Store admin credentials with PBKDF2 and remove legacy hashes (FortiOS 7.2.11+)
• Review REST API keys, remove unknown ones and refresh the rest
The advisory describes credential abuse and names no CVE, so patching alone is not enough: the agencies warn lockouts can need remediation beyond standard patching and password resets. It lists attacker IPs and rogue account names to hunt for, but asks defenders to vet those IOCs before blocking, as some addresses may since have been reassigned.
#DDW #DarkWeb #CyberSecurity #FortiBleed #Fortinet #Ransomware #FBI"
🇺🇸 🚨 FBI AND SECRET SERVICE: FORTIBLEED CAMPAIGN STILL HITTING FORTINET FIREWALLS AND VPNS
A joint FBI and U.S. Secret Service cybersecurity advisory published Oct 6 says FortiBleed, a global credential-compromise campaign against internet-facing Fortinet FortiGate firewalls and SSL VPN gateways, is still active.
• Attackers keep scanning exposed FortiGate devices with previously stolen credentials, using credential stuffing, password spraying and GPU cracking of dumped password hashes
• The campaign exploits reused or leaked credentials and legacy SHA-256 password storage
• Once in, they create new admin accounts for persistence; some victims are locked out when original accounts are deleted or their passwords changed
• Reporting cited by the agencies indicates initial access brokers using the attack chain have passed access to INC/Lynx and Payload ransomware affiliates
• Restrict external management (trusted hosts, then local-in policy) or remove internet admin altogether
• Terminate all admin and VPN sessions; reset all Fortinet VPN and admin passwords
• Enforce phishing-resistant MFA on all remote access and admin accounts
• Review firewall/VPN users and config for unauthorized changes and unrecognized accounts
• Review firewall, VPN, authentication and domain controller logs for lateral movement
• Store admin credentials with PBKDF2 and remove legacy hashes (FortiOS 7.2.11+)
• Review REST API keys, remove unknown ones and refresh the rest
The advisory describes credential abuse and names no CVE, so patching alone is not enough: the agencies warn lockouts can need remediation beyond standard patching and password resets. It lists attacker IPs and rogue account names to hunt for, but asks defenders to vet those IOCs before blocking, as some addresses may since have been reassigned.
🇺🇸 🚨 FBI AND SECRET SERVICE: FORTIBLEED CAMPAIGN STILL HITTING FORTINET FIREWALLS AND VPNS
A joint FBI and U.S. Secret Service cybersecurity advisory published Oct 6 says FortiBleed, a global credential-compromise campaign against internet-facing Fortinet FortiGate firewalls and SSL VPN gateways, is still active.
• Attackers keep scanning exposed FortiGate devices with previously stolen credentials, using credential stuffing, password spraying and GPU cracking of dumped password hashes
• The campaign exploits reused or leaked credentials and legacy SHA-256 password storage
• Once in, they create new admin accounts for persistence; some victims are locked out when original accounts are deleted or their passwords changed
• Reporting cited by the agencies indicates initial access brokers using the attack chain have passed access to INC/Lynx and Payload ransomware affiliates
• Restrict external management (trusted hosts, then local-in policy) or remove internet admin altogether
• Terminate all admin and VPN sessions; reset all Fortinet VPN and admin passwords
• Enforce phishing-resistant MFA on all remote access and admin accounts
• Review firewall/VPN users and config for unauthorized changes and unrecognized accounts
• Review firewall, VPN, authentication and domain controller logs for lateral movement
• Store admin credentials with PBKDF2 and remove legacy hashes (FortiOS 7.2.11+)
• Review REST API keys, remove unknown ones and refresh the rest
The advisory describes credential abuse and names no CVE, so patching alone is not enough: the agencies warn lockouts can need remediation beyond standard patching and password resets. It lists attacker IPs and rogue account names to hunt for, but asks defenders to vet those IOCs before blocking, as some addresses may since have been reassigned.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
